First published: Wed Jul 11 2007(Updated: )
TippingPoint IPS before 20070710 does not properly handle a hex-encoded alternate Unicode '/' (slash) character, which might allow remote attackers to send certain network traffic and avoid detection, as demonstrated by a cmd.exe attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tippingpoint Tipping Point | =400 | |
3com Tippingpoint Ips Tos | =2.2 | |
Tippingpoint Tipping Point | =1200 | |
3com Tippingpoint Ips Tos | =2.5.1 | |
Tippingpoint Tipping Point | =50 | |
3com Tippingpoint Ips Tos | =2.2.1.6506 | |
3com Tippingpoint Ips Tos | =2.1 | |
Tippingpoint Tipping Point | =5000e | |
3com Tippingpoint Ips Tos | =2.2.1 | |
Tippingpoint Tipping Point | =2400e | |
Tippingpoint Tipping Point | =sms | |
3com Tippingpoint Ips Tos | =2.2.3 | |
Tippingpoint Tipping Point | =zpha | |
Tippingpoint Tipping Point | =x505 | |
3com Tippingpoint Ips Tos | =2.2.2 | |
Tippingpoint Tipping Point | =1200e | |
Tippingpoint Tipping Point | =200e | |
3com Tippingpoint Ips Tos | =2.2.4 | |
3com Tippingpoint Ips Tos | =2.1.4.6324 | |
Tippingpoint Tipping Point | =x506 | |
Tippingpoint Tipping Point | =200 | |
3com Tippingpoint Ips Tos | =2.5 | |
Tippingpoint Tipping Point | =600e |
http://security-assessment.com/files/advisories/2007-07-11_Tippingpoint_IPS_Signature_Evasion.pdf
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3701 is classified as a medium severity vulnerability.
To address CVE-2007-3701, upgrade your TippingPoint IPS to version 20070710 or later.
CVE-2007-3701 allows remote attackers to bypass detection by exploiting improper handling of hex-encoded Unicode characters.
CVE-2007-3701 affects all TippingPoint IPS versions prior to 20070710.
Yes, CVE-2007-3701 can enable attackers to send undetected malicious network traffic, potentially leading to successful exploitation.